¦b¨å«¬ªº®Õ¶éºôÀô¹Ò¤¤¡A¸ô¥Ñ¾¹¤@¯ë³B©ó¨¾¤õÀ𪺥~³¡¡At³d»PInternetªº³s±µ¡C³oºØ©Ý¥·µ²ºc¹ê»Ú¤W¬O±N¸ô¥Ñ¾¹¼ÉÅS¦b®Õ¶éºô ¦w¥þ¨¾½u¤§¥~¡A¦pªG¸ô¥Ñ¾¹¥»¨¤S¥¼±Ä¨ú¾A·íªº¦w¥þ¨¾½dµ¦²¤¡A´N¥i¯à¦¨¬°§ðÀ»ªÌµo°_§ðÀ»ªº¤@¶ô¸õªO¡A¹ï¤º³¡ºô¸ô¦w¥þ³y¦¨ «Â¯Ù¡C ¥»¤å¥HCisco 2621¸ô¥Ñ¾¹¬°¨Ò¡A¸Ô²Ó¤¶²Ð±N¤@¥x¸ô¥Ñ¾¹°t¸m¬°³ùÂS¸ô¥Ñ¾¹ªº¹ê²{¤èªk¡A¨Ï¤§¦¨¬°®Õ¶éºô©è±s¥~³¡§ðÀ»ªº²Ä¤@¹D ¦w¥þ¿Ã«Ì»Ù¡C ¤@¡B¾A¥Î©ó³X°Ýªíªº¦w¥þ¨¾½dµ¦²¤ 1. ¨¾¤î¥~³¡IP¦a§}´ÛÄF ¥~³¡ºô¸ôªº¨Ï¥ÎªÌ¥i¯à·|¨Ï¥Î¤º³¡ºôªº¦XªkIP¦ì§}©ÎªÌ´`Àô¦ì§}§@¬°¨Ó·½¦ì¸m¡A±q¦Ó¹ê²{«Dªk³X°Ý¡C°w¹ï¦¹Ãþ°ÝÃD¥i«Ø¥ß¦p¤U ³X°Ý¦Cªí¡G access-list 101 deny ip 10.0.0.0 0.255.255.255 any access-list 101 deny ip 192.168.0.0 0.0.255.255 any access-list 101 deny ip 172.16.0.0 0.0.255.255 any ! ªý¤î¨Ó·½¦ì¸m¬°¨p¦³¦a§}ªº©Ò¦³³q«H¬y¡C access-list 101 deny ip 127.0.0.0 0.255.255.255 any ! ªý¤î¨Ó·½¦ì¸m¬°¦^Àô¦a§}ªº©Ò¦³³q«H¬y¡C access-list 101 deny ip 224.0.0.0 7.255.255.255 any ! ªý¤î¨Ó·½¦ì¸m¬°¦h¥Øªº¦ì§}ªº©Ò¦³³q«H¬y¡C access-list 101 deny ip host 0.0.0.0 any ! ªý¤î¨S¦³¦C¥X¨Ó·½¦ì¸mªº³q«H¬y¡C ª`¡G¥i¥H¦b¥~³¡³s±µªº¦V¤º¤è¦V¨Ï¥Î101¹LÂo¡C 2. ¨¾¤î¥~³¡ªº«Dªk±´´ú «Dªk³X°ÝªÌ¹ï¤º³¡ºô¸ôµo°_§ðÀ»«e¡A©¹©¹·|¥Îping©Î¨ä¥L©R¥O±´´úºô¸ô¡A©Ò¥H¥i¥H³z¹L¸T¤î±q¥~³¡¥Îping¡Btracerouteµ¥±´´úºô ¸ô¨Ó¶i¦æ¨¾½d¡C¥i«Ø¥ß¦p¤U³X°Ý¦Cªí: access-list 102 deny icmp any any echo ! ªý¤î¥Îping±´´úºô¸ô¡C access-list 102 deny icmp any any time-exceeded ! ªý¤î¥Îtraceroute±´´úºô¸ô¡C ª`¡G¥i¦b¥~³¡³s±µªº¦V¥~¤è¦V¨Ï¥Î102¹LÂo¡C¦b³o¸Ì¥Dn¬Oªý¤îµª´_¿é¥X¡A¤£ªý¤î±´´ú¶i¤J¡C 3. «OÅ@¸ô¥Ñ¾¹¤£¨ü§ðÀ» ¸ô¥Ñ¾¹¤@¯ë¥i¥H³z¹Ltelnet©ÎSNMP³X°Ý¡AÀ³¸Ó½T«OInternet¤W¨S¦³¤H¯à¥Î³o¨Ç¨óij§ðÀ»¸ô¥Ñ¾¹¡C°²©w¸ô¥Ñ¾¹¥~³¡³s±µserial0ªºIP¬° 200.200.200.1¡A¤º³¡³s±µfastethernet0ªºIP¬°200.200.100.1¡C¥i¥H¥Í¦¨ªý¤îtelnet¡BSNMPªA°Èªº¦V¤º¹LÂo«OÅ@¸ô¥Ñ¾¹¡C«Ø¥ß¦p¤U¦C ªí¡G access-list 101 deny tcp any 200.200.200.1 0.0.0.0 eq 23 access-list 101 deny tcp any 200.200.100.1 0.0.0.0 eq 23 access-list 101 deny udp any 200.200.200.1 0.0.0.0 eq 161 access-list 101 deny udp any 200.200.100.1 0.0.0.0 eq 161 ª`: ¦b¥~³¡³s±µªº¦V¤º¤è¦V¨Ï¥Î101¹LÂo¡C·íµM³o·|¹ïºÞ²zûªº¨Ï¥Î³y¦¨¤@©wªº¤£«K¡A³o´N»Ýn¦b¤è«K»P¦w¥þ¤§¶¡°µ¥X¿ï¾Ü¡C 4. ªý¤î¹ïÃöÁä³s±µ°ðªº«Dªk³X°Ý ÃöÁä³s±µ°ð¥i¯à¬O¤º³¡¨t²Î¨Ï¥Îªº³s±µ°ð©ÎªÌ¬O¨¾¤õÀ𥻨¼ÉÅSªº³s±µ°ð¡C¹ï³o¨Ç³s±µ°ðªº³X°ÝÀ³¸Ó¥[¥H¨î¡A§_«h³o¨Ç³]³Æ ´N«Ü®e©ö¨ü¨ì§ðÀ»¡C«Ø¥ß¦p¤U³X°Ý¦Cªí¡G access-list 101 deny tcp any any eq 135 access-list 101 deny tcp any any eq 137 access-list 101 deny tcp any any eq 138 access-list 101 deny tcp any any eq 139 access-list 101 deny udp any any eq 135 access-list 101 deny udp any any eq 137 access-list 101 deny udp any any eq 138 access-list 101 deny udp any any eq 139 5. ¹ï¤º³¡ºô¸ôªº«n¦øªA¾¹¶i¦æ¨î ¹ï©ó¨S¦³°t³Æ±M¥Î¨¾¤õÀ𪺮նéºô¸ô¡A±Ä¥Î°ÊºA¤À²Õ¹LÂo§Þ³N«Ø¥ß¹ï«n¦øªA¾¹ªº³X°Ý¨î´NÅã±o¤×¬°«n¡C¹ï©ó°t³Æ¤F±M¥Î ¨¾¤õÀ𪺮նéºô¸ô¡A¦¹¶µ¥ô°È¥i¥H¦b¨¾¤õÀð¤W§¹¦¨¡A³o¼Ë¥i¥H´î»´¸ô¥Ñ¾¹ªºt¾á¡CµL½×¬O¾A¥Î©ó¸ô¥Ñ¾¹¹ê²{¡AÁÙ¬O¦b¨¾¤õÀð¤W §¹¦¨³]¸m¡Aº¥ý³£À³¸Ó¨î©w¤@®M³X°Ý³W«h¡C¥i¥H¦Ò¼{«Ø¥ß¦p¤Uªº³X°Ý³W«h: ¡´ ¤¹³\¥~³¡¨Ï¥ÎªÌ¨ìWeb¦øªA¾¹ªº¦V¤º³s±µ½Ð¨D¡C ¡´ ¤¹³\Web¦øªA¾¹¨ì¥~³¡¨Ï¥ÎªÌªº¦V¥~µª´_¡C ¡´ ¤¹³\¥~³¡SMTP¦øªA¾¹¦V¤º³¡«H¥ó¦øªA¾¹ªº¦V¤º³s±µ½Ð¨D¡C ¡´ ¤¹³\¤º³¡«H¥ó¦øªA¾¹¦V¥~³¡SMTP¦øªA¾¹ªº¦V¥~µª´_¡C ¡´ ¤¹³\¤º³¡«H¥ó¦øªA¾¹¦V¥~DNS¬d¸ß¡C ¡´ ¤¹³\¨ì¤º³¡«H¥ó¦øªA¾¹ªº¦V¤ºªºDNSµª´_¡C ¡´ ¤¹³\¤º³¡¥D¹q¸£ªº¦V¥~TCP³s±µ¡C ¡´ ¤¹³\¹ï½Ð¨D¥D¹q¸£ªº¦V¤ºTCPµª´_¡C ¨ä¥L³X°Ý³W«h¥i¥H®Ú¾Ú¦U¦Ûªº¹ê»Ú±¡ªp«Ø¥ß¡C¦C¥X¤¹³\ªº©Ò¦³³q«H¬y«á¡A³]p³X°Ý¦Cªí´NÅܱo²³æ¤F¡Cª`·NÀ³±N©Ò¦³¦V¤º¹ï¸Ü À³¥Î©ó¸ô¥Ñ¾¹¥~³¡³s±µªºIN¤è¦V¡A©Ò¦³¦V¥~¹ï¸ÜÀ³¥Î©ó¸ô¥Ñ¾¹¥~³¡³s±µªºOUT¤è¦V¡C ¤G¡B±`¨£§ðÀ»¤â¬q¤Î¨ä¹ïµ¦ 1. ¨¾¤î¥~³¡ICMP«©w¦V´ÛÄF §ðÀ»ªÌ¦³®É·|§Q¥ÎICMP«©w¦V¨Ó¹ï¸ô¥Ñ¾¹¶i¦æ«©w¦V¡A±N¥»À³°e¨ì¥¿½T¥Ø¼Ðªº¸ê°T«©w¦V¨ì¥¦Ì«ü©wªº³]³Æ¡A±q¦ÓÀò±o¦³¥Î ¸ê°T¡C¸T¤î¥~³¡¨Ï¥ÎªÌ¨Ï¥ÎICMP«©w¦Vªº©R¥O¦p¤U¡G interface serial0 no ip redirects 2. ¨¾¤î¥~³¡·½¸ô¥Ñ´ÛÄF ·½¸ô¥Ñ¿ï¾Ü¬O«ü¨Ï¥Î¸ê®ÆÃì¸ô¼h¸ê°T¨Ó¬°¸ê®Æ³ø¶i¦æ¸ô¥Ñ¿ï¾Ü¡C¸Ó§Þ³N¸ó¶V¤Fºô¸ô¼hªº¸ô¥Ñ¸ê°T¡A¨Ï¤J«IªÌ¥i¥H¬°¤º³¡ºôªº¸ê ®Æ³ø«ü©w¤@Ó«Dªkªº¸ô¥Ñ¡A³o¼Ë쥻À³¸Ó°e¨ì¦Xªk¥Øªº¦aªº¸ê®Æ³ø´N·|³Q°e¨ì¤J«IªÌ«ü©wªº¦a§}¡C¸T¤î¨Ï¥Î·½¸ô¥Ñªº©R¥O¦p ¤U¡G no ip source-route 3. ¨¾¤îµs¥Î¤º³¡IP¦a§} §ðÀ»ªÌ¥i¯à·|µs¥Î¤º³¡IP¦a§}¶i¦æ«Dªk³X°Ý¡C°w¹ï³o¤@°ÝÃD¡A¥i¥H§Q¥ÎCisco¸ô¥Ñ¾¹ªºARP©R¥O±N©T©wIP¦a§}¸j©w¨ì¬Y¤@MAC¦a §}¤§¤W¡C¨ãÅé©R¥O¦p¤U¡G arp ©T©wIP¦a§} MAC¦a§} arpa 4. ¦b·½¯¸¥x¨¾¤îsmurf n¦b·½¯¸¥x¨¾¤îsmurf¡AÃöÁä¬Oªý¤î©Ò¦³ªº¦V¤º¦^Åã½Ð¨D¡C³o´Nn¨¾¤î¸ô¥Ñ¾¹±N«ü¦Vºô¸ô¼s¼½¦a§}ªº³q«H¬M®g¨ì°Ï°ìºô¸ô¼s¼½¦a §}¡C¥i¥H¦bLAN³s±µ¤è¦¡¤¤¿é¤J¦p¤U©R¥O¡G no ip directed-broadcast ¤T¡BÃö³¬¸ô¥Ñ¾¹¤W¤£¥ÎªºªA°È ¸ô¥Ñ¾¹°£¤F¥i¥H´£¨Ñ¸ô®|¿ï¾Ü¥~¡A¥¦ÁÙ¬O¤@¥x¦øªA¾¹¡A¥i¥H´£¨Ñ¤@¨Ç¦³¥ÎªºªA°È¡C¸ô¥Ñ¾¹°õ¦æªº³o¨ÇªA°È¥i¯à·|¦¨¬°¼Ä¤H§ðÀ» ªº¬ð¯}¤f¡A¬°¤F¦w¥þ°_¨£¡A³Ì¦nÃö³¬³o¨ÇªA°È¡C ³z¹L¥H¤W¤¶²Ðªº¦UºØ¤èªk¡A§Ú̦¨¥\¦a±N¤@¥x´¶³q¸ô¥Ñ¾¹°t¸m¬°¤@¥x³ùÂS¸ô¥Ñ¾¹¡A¦b¨S¦³¼W¥[¥ô¦ó§ë¤Jªº±¡ªp¤U¡A´£°ª¤F¾ãÓ ¶é°Ïºôªº¦w¥þ©Ê¡C¦ýÀ³¸Ó»¡©úªº¬O¡A³ùÂS¸ô¥Ñ¾¹ªº¹ê²{¬O¥HÄ묹¾ãÓºô¸ôªº®Ä²v¬°¥N»ùªº¡A¥i¯à·|¼vÅT¨ì¶é°Ïºô¹ï¥~³X°Ýªº³t «×¡C |